Prompt Later privacy policy
Scope and purpose
Prompt Later is a browser extension that schedules user-written text messages for specific existing conversations on supported AI websites. The extension has no application backend, user account service, advertising system, or telemetry endpoint.
This policy covers the extension. The Chrome Web Store, the site hosting this policy, and the AI providers may process information under their own policies.
Data handled by the extension
The extension handles the messages you enter, selected conversation URLs and provider names, scheduling and time-zone settings, job identifiers and statuses, and activity records. Activity can include a message preview of up to 160 characters, the target URL, timestamps, and a delivery explanation.
With your permission, it reads a selected tab URL and matching provider-tab URLs. It inspects the saved conversation page to find the composer and check draft, busy, and error states. Depending on the delivery setting you choose, it preserves, submits, or replaces existing composer text; it inserts scheduled text when required and determines whether matching user messages appeared. This page inspection is transient; Prompt Later does not store or export conversation transcripts or AI responses, or collect general browsing history.
The extension does not store account passwords and does not read provider account passwords, authentication cookies, or API keys.
Local storage and encryption
Saved messages, conversation URLs, schedule definitions, and activity are stored using AES-256-GCM encryption in local extension storage. Each write uses a fresh random nonce. Plaintext is used in memory and displayed where needed to operate the extension.
A random 256-bit AES CryptoKey is generated and stored as a non-exportable key in extension-origin IndexedDB in this browser profile. The raw key is not exported to chrome.storage.local. No passphrase is required, so schedules resume automatically after a browser restart, extension reload, or update. This is not hardware-backed or operating-system-keychain protection, and someone controlling the browser or profile may still cause the data to be decrypted.
Every write is verified by reading the stored record back and decrypting it before it is trusted. Local and session extension storage are restricted to trusted extension contexts.
A vault that was protected with a passphrase by an earlier version cannot be opened by this version. Nothing is reset: the extension reports how to recover it by reinstalling the earlier version and turning passphrase protection off.
The extension may temporarily retain a second encrypted copy while verifying a storage migration. Older plaintext records are removed only after the encrypted copy is saved and verified, so recoverable copies are preserved if a migration is interrupted.
Encryption does not protect data from someone controlling an already unlocked browser, inspecting its memory, or accessing your signed-in provider accounts. Losing the browser profile or its device key may make encrypted data permanently unreadable.
Use, transmission, and sharing
Data is used only to provide the scheduling, delivery, safety, and activity features you request. The extension does not sell user data, use it for advertising or credit decisions, or send it to a Prompt Later server or an analytics service.
When a job runs, the extension opens or reuses the selected provider's HTTPS conversation page and sends your configured text through that website using your signed-in session. The provider receives and processes the message as an ordinary chat message under its own terms, account limits, and privacy policy. Opening the page also creates the provider's ordinary website traffic.
Store installation/update services and the host of this policy may receive standard traffic information when you use them. Those services are separate from the extension; this policy does not promise that third-party services keep no logs.
Retention and deletion
Saved jobs, including completed jobs, remain in the encrypted vault until you delete them. Sending a message does not automatically delete its saved job. Deleting a job does not delete its separate activity records. The extension retains up to the latest 200 finalized activity records; older finalized records are pruned during state updates.
The encrypted vault and its device or session keys are not synchronized by Prompt Later to another device. Uninstalling the extension removes its local extension data through Chrome. Copies made by you, browser/profile backups, operating-system backups, and records retained by an AI provider are not deleted by uninstalling Prompt Later.
To remove a message already sent to a provider, use that provider's own deletion controls and policies.
Your controls and important limits
You choose the conversation, text, time, recurrence, time zone, late-run policy, and how existing composer drafts are handled. You can edit, pause, or delete saved jobs and revoke site access through Chrome. Revoked access or unavailable encrypted storage blocks new scheduled delivery attempts. A send already underway may complete; running jobs cannot be edited, paused, or deleted.
Keep the computer awake, the browser running, and the target provider signed in. Scheduled times can be delayed. Automatic restart recovery resumes schedules and applies each job's late policy, so overdue messages may send immediately.
Saved data is encrypted automatically and there is no passphrase to set or remember. Removing the extension deletes its saved data, including the device key.
Changes and contact
Material changes to data handling will be reflected in this policy and the extension's disclosures before the changed handling is enabled.
If you email the support address, the information you choose to send is delivered to that inbox through email providers, including Gmail. Support correspondence is outside the extension's encrypted vault. Prompt Later does not automatically email logs or transcripts. Do not send vault passphrases, provider passwords, cookies, or API keys.
Contact: promptlater.support@gmail.com